CVE-2024-40725
Apache
CVE-2024-40725 allows for potential source code disclosure in Apache HTTP Server 2.4.61, even with a partial fix for CVE-2024-39884. This vulnerability arises because "AddType" configurations can, under specific indirect file requests, reveal local file contents. While the CVSS score is 5.3, SOCRadar's Vulnerability Risk Score (SVRS) is 62, indicating a moderate risk, though not critical. The underlying issue involves a CWE-668 (Exposure of Resource to Wrong Sphere). Notably, exploits are available and being used "In The Wild". This means attackers are actively attempting to leverage this flaw. Immediate mitigation, such as upgrading to Apache HTTP Server 2.4.62, is strongly recommended to prevent the disclosure of sensitive code. This is significant due to the potential for attackers to gain insights into the server's inner workings and potentially escalate attacks.
Description
CVE-2024-40725 is a partial fix for CVE-2024-39884 in Apache HTTP Server 2.4.61. It involves the legacy content-type based configuration of handlers, where "AddType" and similar configurations can lead to source code disclosure of local content under specific circumstances. This vulnerability is actively exploited in the wild.
Key Insights
- SVRS Score: 56, indicating a moderate risk.
- Exploit Status: Active exploits have been published.
- CISA Warning: The Cybersecurity and Infrastructure Security Agency (CISA) has warned of the vulnerability, calling for immediate and necessary measures.
- Threat Actors: Not specified in the provided information.
Mitigation Strategies
- Upgrade to Apache HTTP Server version 2.4.62 or later.
- Review and adjust "AddType" and similar configurations to prevent source code disclosure.
- Implement web application firewalls (WAFs) to block malicious requests.
- Regularly monitor logs and security alerts for suspicious activity.
Additional Information
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.